Adding transactions in a composite role menu

Hello All,
I want to add transactions in the menu for a composite role. but I do not see the option to add it. Please guide how would it be possible. Do I need to create single roles and merge the menus for them or can I create aa separate menu for the composite role?
Thanks in advance.
Regards,
Anju

Hi There,
No first of all you cant add transactions to the menu of a composite role as a composite role is a collection of several single roles.
What you can do is create a single role, make addition/ deletions of tcodes inside the single role which will automatically reflect in the menu tab of single role and then you can add this single role to the composite role.
If you want to make changes to the tcodes from the menu tab you need to go to the single role and make changes which will reflect automatically, but thru composite role its not possible to make changes to the menu tab simply because the composite role takes all the tcodes from the single roles contained within it.
Hope this answers your query
Best ,
Suchitra

Similar Messages

  • Add a single role to different composite roles in one step

    Hello everybody,
    I am working on SAP authorizations, and we often have the situation that a new Tcode is developed and a new role for this Tcode needs to be created.
    Than this new role needs to be added to many different composite roles (sometimes more than 100). At the moment I enter the single role to the composite role and regenerate the menu and this one by one. After that I add them with PFCG_MASS_TRANSPORT to my transport request.
    I don't want to believe that there is no easier way. Any ideas?
    Thank you
    Flo

    Hi Soma,
    great to find a place to be welcome..Thanks
    What you wrote definitely makes sense, but we agreed that every user only gets one composite role assigned and this composite role contains all single roles needed for his job. We do not assign single roles to users.
    The requirement is that every finance guy should get access to it (by the way, it is a report) unfortunately we have many different sites and may different composite roles for the different positions in the finance area.
    And I did not identify a role which is part of every composite role in the finance area, so I would either have to add it to the most common role present in these composite roles and additionally create a new role which gets assigned to the composite roles where I add the T-Code to is not present.
    -> In this example I would add one T-Code to two roles. Which our security manager disallowed me...
    or make this role available in all finance composite roles, which will give these employees access to other T-Codes which are part of the role but which they should not receive.
    -> Which again... our security manager disallowed me...
    So the only solution I imagined was to create a new role which contains this T-Code and to add this role one by one to every composite role.
    And at the end, your concept is also taken into account because the design of this role is open and if we get a new reporting T-Codes which again need to be added to all Finance guys, I definitely add it to this role
    Comments?
    Cheers
    Florian

  • How to find the T-codes that's in a Single Role & Composite Role??

    Hi all,
    Some of the user have authorization to particular t-codes. However single roles are not created for them.
    Now I need to assign authorization to that particular t-code to a new employee.
    Since the single role is not there, I do not know how to find if it is inside a composite role.
    Which table should I find all the t-codes that are assigned to a single role / composite role?
    pls help.
    Regards,
    Pri

    Rakesh Kulkarni wrote:>
    > Table AGRS_TCODES give the roles with their tcode assignment.
    Beware of AGR_TCODES, it only reports transactions entered into the role menu. If you query table AGR_1251 filtered on object S_TCODE you get the actual transaction authorizations.
    Besides that, authorizations are always in single roles, so if you cannot find them there there's no point in searching through the composites.

  • How to remove transaction that was added under Menu - Role Menu

    We have roles that we need to remove some transactions.
    These transactions were added under Menu - Role Menu and expanded for ex: Logistics and Picked Miro transaction.
    When I go to PFCD and check under s_tcode I cannot remove Miro transactions since it's grayed out.
    The only way to remove this is to go back to the Menu and do a find on miro and work through the menu until I get to Miro transaction and then delete it.
    Is there another way to accomplish this.
    Thanks
    Joe

    This is the intended way a role built from a menu works. What might be the use of an authorization without any corresponding transaction to start it? It is only a risk...
    Unless of course you know better or design differently and don't make the effort to adjust SU24, then you can insert manually or cause "changed" authorizations, but PFCG will not look at it from a "your own fault" view and not adjust it or protect it against illogical changes.
    To use the discipline of the one approach but keep the flexibility of manual authorizations is not possible for S_TCODE, S_RFC and S_SERVICE objects (the entry points).
    Cheers,
    Julius
    PS:
    > Total Questions:  42 (36 unresolved) 
    Please follow-up on your unresolved questions. There is a limit now of 10 open questions asked since July 2008.

  • Authorization data is updated after adding transaction in role menu

    Hi Experts,
    When we add transaction in the menu of a role, the objects and organization levels related to the transaction are not getting reflected in the authorization data. Only object S_TCODE is coming. As an example if we add transactions MM01, MM02, MM03 in the role menu, under authorization data only object S_TCODE is coming. No other authorization object or org level are coming.
    This is only happening in one system. Kindly suggest.
    Thanks and Regards,
    Amit Jana.

    Hi Jurjen,
    Thanks a million for your reply. The customer tables has been filled up from su25 and this has solved the issue.
    Thanks and Regards
    Amit Jana.

  • No authorization to add transaction to role menu

    MODS: IF YOU ARE GOING TO DELETE MY POSTS..AT LEAST EMAIL ME TO LET ME KNOW WHY YOU ARE DELETING THEM SO I CAN RE-WORD IT TO ACCOMMODATE YOUR ISSUE. THIS IS THE THIRD TIME YOU HAVE DELETED ONE OF MY POSTS WITH NO EXPLANATION AND IF THIS FORUM ISNT FOR ASKING QUESTIONS LIKE THIS...THEN WHAT IS IT FOR?
    To the question:
    I am able to do add a transaction to a role in our production environment without issue. Trying to add it in in Development system gives me the following error:
    No authorization to add transaction <transaction name> to role menu.
    When I look at SU53 it tells me that it failed on Authorization Object s_user_tcd Field TCD value Z_RICKTEST
    It then shows me 4 profiles with that auth object and field and a value of PFCG.
    I can run the program Z_RICKTEST with no issue in either system.
    Can anyone shed some light on why this is happening?

    The reject mail contains a link to the forum rules. If you (had) read that you would understand.
    Reason is that you have no basic training, make no effort to read the application documentation and then make changes in production and want to know from us how it works.
    Imagine if everyone did that? Imagine what the systems would all look like?
    These discussion areas are not a substitute for basic training!
    Thread locked!

  • Issue while adding BW reports to role menu

    Hi All,
    Today, I was trying to assign a list of BW reports to a partcular role in our project. As i started assigning the reports from menu
    tab in PFCG, I observed that all the reports are getting stored with same name "RRMX - Business Warehouse report "
    I also observed that all the reports have only one auth obj S_TCODE, when I checked in auth tab.
    As, Iam new to BW security, I need guidance here.
    ->Is it normal for all the reports to get saved with same name in role menu?
    ->Also, I need to confirm if the reports given to me are already created and active reports, How can i check it?
    ->Also suggest me the proper way to assign reports to the role.
    Regards,
    Brahmeshwar.

    > ->Is it normal for all the reports to get saved with same name in role menu?
    Unfortunately these BW-reports are all started by t-code RRMX. PFCG does not know what is behind RRMX. The t-code in PFCG is always 'RRMX'
    > ->Also, I need to confirm if the reports given to me are already created and active reports, How can i check it?
    hmmm,.... maybe execute them?
    > ->Also suggest me the proper way to assign reports to the role.
    well normally simply press the 'add report' button on the menu tab of pfcg, then select as per your choice.
    BW-REports (RRMX) are a bit different....
    There is a note from BW giving some information for BW-admins who have to work on backend and maintain roles....
    note # 316470
    b.rgds,
    Bernhard

  • Stopping user compare when saving composite roles in 4.6c basis pack 25?

    One of the environments I look after is a 4.6c system with basis pack 25 – they can’t upgrade as it breaks a great deal of very heavy customisation in that system.
    We have encountered an issue with the saving of composite roles in that system - when a role is saved we must sit through a very long period of “user distribution in role XXX” while the system performs a user compare of every singular role in that composite role.  This is very painful as it can take nearly half an hour simply to save the composite role – we then need to rebuild the menu and compress it (we use the composite role’s menu structure).  The odd thing is that this behaviour wasn’t apparent for many years – it suddenly started happening about 2-3 years ago to a previous administrator but he wasn’t aware of any changes going through, it just began to force these lengthy compares on him when saving composites.
    I’ve tried in vain to disable this forced compare on every save – I’ve tried the PRGN_CUST modifications including adding the lines “AUTO_USERCOMPARE” with a value of “NO” and “USRCOMPARE_PFUD” with a value of “YES” to try and stop the profile generator from doing this but to no avail.  Unless these settings need a restart of the system to take effect (do they?) I’m at a loss to find any other options.
    The menu setting in the profile generator of “automatic user master adjustment when saving role” is switched off – though setting “auto_usercompare” seems to have broken the ability to bring up the “settings: role maintenance” dialogue box anyway.
    We have a very large number of roles to modify and would be grateful if anyone could offer any advice here.
    Thanks
    DT

    the problem with your issue is that none of use can reproduce that phenomenon, since none of use has that combination of primal release/support package level at hand any longer (at least i think so). so there's only two options left to you:
    first: update this special application until the problem goes away - do so by adding note after note on the very subject, like the one i mentioned plus [905924|https://websmp130.sap-ag.de/sap(bD1kZSZjPTAwMQ==)/bc/bsp/spn/sapnotes/index2.htm?numm=905924&nlang=EN&smpsrv=https%3a%2f%2fwebsmp107%2esap-ag%2ede] plus [662484|https://websmp130.sap-ag.de/sap(bD1kZSZjPTAwMQ==)/bc/bsp/spn/sapnotes/index2.htm?numm=662484&nlang=EN&smpsrv=https%3a%2f%2fwebsmp107%2esap-ag%2ede] and stop only when you hit one that is not implementable using SNOTE but only by implementing a support-package -> this will obviously be the point where you're stuck then.
    (and yes - for the sake of rob burbank: there are several other ways to implement corrections aside from SNOTE).
    second: open a call with SAP. mind you, this might become a lenghty one since they will also give you note after note ...
    as i said, i'm pretty sure no one in here can help you doing a proper analysis anymore (but maybe i'm wrong).
    anyone - any other (better) suggestions?

  • CUA problem with composite role

    Hello experts, I have a problem with a composite role in my CUA parent system. If you look at the roles tab you will see one of the child roles has a name of child CUA system in the 'target sys' column. the rest all have 'user system'. Can anyone explain how this 'target sys' column is defined?
    Thanks
    Dave Wood

    I do not know if you have solved this issue, but the target system is defined within your single role on you menu tab.
    No what happens is that in transaction SM30 table SSM_RFC you define system variable linked to your logical system.
    This variable determines that when you import roles from another system by means of transaction PFCG > Read from other system from RFC and you select your variable the system will automatically default in the target system field the system it is suppose to go back to.
    So this way when you distibute the roles it will only go back to that particular target system, and you do not need to specify and guess where the role came from.
    Try removing that table entry in SM30 SSM_RFC and see if that way you will be able to remove the target system from the role.
    However it is not a bad thing to have activated. If you are working with position base authorizations and you have more than 1 system, you define 1 composite role for all the roles, for all the systems and you will be able to see where the composite resides by means of the target value.
    Hope this makes sense.
    Regards
    Sonja

  • Mass role creation and addition of tcodes to role menu

    Hi Folks,
    We've a requirement of building 1000's of single roles for an implementation. Our security matrix is ready with the role names and the list of tcodes to be embedded in each of these roles. What I would like to know is if we can automate a part of the process of role building i.e the following 3 steps only.
    1. Creation of the Role
    2. Addition of the tcodes in the role menu
    3. Save
    I'm aware of Ecatt/LSMW through which we can create the roles but i'm not sure if we can add the tcodes to the menu of the roles since the number of tcodes to be populated in each role will vary.
    Could anyone of you shed some light if it is possible to automate the addition of  tcodes to the role menu taking into consideration that each role will have different number of tcodes to be added to the menu and what's the best possible way to achieve this if there exists one.
    Thanks in advance for your time and suggestions!
    Guest...

    Whilst I agree that there are probably too many roles being built here, which is more of an issue with the role design / strategy, the issue of how to easily create a role for a given list of transactions is something that SAP supports via the import menu from text file option in PFCG.
    Yes you may need to write a script to cycle through all the possible role names, but we have recently had to build some roles based on actual usage, so exported transaction usage history to excel and then formatted the transactions into text files that could be imported to build the role menu.
    You will still then need to ensure any object authorisation object have the correct values set - i.e. not just starred in - but as one of the pains in build a role is getting the menu to look reasonable, I'd suggest having a look at this approach.
    Copy Menus -> Import from File is the function in PFCG in the menu tab for the role you are building
    OSS note 389675 has details of what the text file of transactions for the menu should look like.
    That should answer the question posed, rather than criticising the role design being followed.

  • Role Menu for ESS (WDA) in SAP NWBC

    Dear experts,
    I am implementing ESS&MSS using SAP NWBC. For this use the following documentation:
    Configuration of the Role Menu for ESS (WDA) in SAP NWBC - SAP Documentation
    SAP delivers the composite role SAP_EMPLOYEE_ESS_WDA_2.
    1. Call up transaction PFCG and create or copy your customer-specific role based on the standard shipped composite role for ESS (WDA), SAP_EMPLOYEE_ESS_WDA_2 in the customer name space (Z_*.
    I have copied this role with the singles roles
    My first question: Should modify my composite role for add a new folder that content two applications WDA customer or this should do it in the single role ? How Can do it?
    My second question:
    What I dont can display the folder in top screen "Employee Self-Service"---"Employee Self-Service XX"---"Employee Self-Service2"(See Image leff)
    Thanks

    Hi Armin,
    For NWBC you must place transactions under the second folder down (or at least this is how its works for NWBC for ERP roles). Standard NWBC roles have 'Role menu' as top folder and then (generally) one main folder under that - like 'Purchasing'. Transactions should go under this folder or under subsequent sub-folder.
    There are additional parameters using right click 'Details for Net Weaver Business Client' under PFCG also - but assume your documentation has explained this to you.
    Regards,
    Craig

  • Updating Role Menu.

    Hi People,
        In one of our customer site, Whenever we have to add transaction code to a role, instead of adding it to role menu we include it in S_TCODE and add corresponding objects manually. Now we would like to update role menu with the transaction codes that have been included in past in S_TCODE. Doing this task manually is tedious activity. Probably i would have to look at the table AGR_HIER and AGR_1251 and find the difference of transaction codes not updated in role menu and update them manually.
    Is there anyway to generate role menu?
    Thanks in anticipation.
    Regards,
    Priyank

    Hi Priyank,
    I am aware of a litlle workaround, which you could consider.
    1.
    identify the profilename for which you want a role with corresponding menue. Either in PFCG->Tab authorizations or you could create a list of all of your roles with manual S_TCODE-authorizations by selecting AGR_1250 in SE16 with option OBJECT=S_TCODE and MODIFIED=U.
    2.
    Enter the profilename in SU02 and copy the profile to a new name.
    Please pay attention to the popup you get, when you copy the generated profile into a manual profile. Do not perform any changes to the original role at this moment until you are finished....
    3.
    Activate the new manual profile (also in SU02 by pressing 'activate' twice).
    4.
    Go to SU25
    5.
    Start point 6
    6.
    Your new manual profile appears now in the list
    7.
    Generate a new role out of this manual profile with the options you desire.
    8.
    Maintain the authorizations in PFCG for the new role/profile
    Done.
    I hope this information helps a bit to avoid many manual steps....
    b.rgds, Bernhard

  • Post EhP4 Upgrade - SUIM does not show Composite Role report

    Hi
    I'm having trouble in SUIM after we upgraded to EhP4. Specifically in the Roles by complex criteria selection.
    When a list of single roles is displayed, I select a role and click on Contained in Composite roles (3-arrow button)
    Instead of showing me the list of comp role that selected single role is found in, I get a collective list of all the single roles that are located in the same composite roles as the selected single role is found in.
    Any help out there?
    Regards,
    Yergat

    Hi,
    Refer the below SAP Notes:
    SAP Note 1393940 - SUIM| Incorrect results when searching for profile and roles.
    SAP Note 1543140 - SUIM|RSUSR070 long text, USER_COMMAND_AGR
    Regards,
    Raghu
    Added a new SAP note, which is also relevant

  • Role Menu

    Hello All,
    What we are trying to do is to Web Enable a Z Transaction in BW 3.0b. We have a transaction
    ZXXX and included that transaction in the role menu. The role menu also has other BW Web reports attached to it.
    When we execute the link for role menu, it shows only the BW Web reports and doesn’t show this ABAP.
    (Note: We are on BW 3.0b that has an architecture that is on WAS like SAP 4.7)
    Thanks and Regards
    Pradeep Bhojak

    Pradeep,
    The role menu shows only objects that can be executed over the web. The transaction cannot.
    You will need to work with ITS and put in the URL to access the transaction through ITS in the role menu to make this work.
    Other option is to develop a BSP application around the transaction.
    Cheers
    Aneesh

  • Need to identify Table or Report Name or Transaction Name for mapping roles

    In PFCG transaction, we can see the simple roles available inside a composite role.
    But I want to identify the table name or report name or transaction name which will help me to identify simple roles for all composite roles.
    Looking for your soonest reply.
    With Regards,
    Santanu Samantroy

    Thank You for your quick turn around.
    This table can help us to find out the simple/derived roles inside all composite roles at once.
    Do you have any idea, of any report/transaction can provide the same result.
    Similarly please let me know, if there is any report/transaction/table which can provide mapping of all simple and derived roles.
    Transaction code SUIM does not provide this facility.
    Thank You once again.
    Santanu

Maybe you are looking for